• A dormant Microsoft Outlook add-in has been weaponized by attackers to steal thousands of login credentials and credit card numbers. The incident, identified by security researchers as the first known malicious Office add-in found in the wild, exposed a critical flaw in how Microsoft distributes third-party tools. The “Zombie” App In 2022, a developer published […]

    The post Microsoft Outlook Add-In Stolen 4000 Accounts and Credit Card Numbers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake CAPTCHA attacks are now a key entry point for a new wave of LummaStealer infections, with CastleLoader loaders turning simple web clicks into full system compromise. Less than a year after a major law-enforcement takedown, the infostealer’s operators have rebuilt at scale and are again harvesting credentials, crypto wallets, and personal data worldwide. LummaStealer […]

    The post Fake CAPTCHA Attacks Exploit Key Entry Point for LummaStealer Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new era of AI vulnerability has arrived, and it is far more dangerous than simply tricking a chatbot into saying something rude. New research released this week demonstrates how attackers can weaponize everyday tools such as Google Calendar and Zoom to spy on users without ever prompting them to click a link. In a […]

    The post Promptware – Hackers Exploit Google Calendar Invites to Stealthily Stream Victim’s Camera via Zoom appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple on Wednesday released iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS updates to address a zero-day flaw that it said has been exploited in sophisticated cyber attacks. The vulnerability, tracked as CVE-2026-20700 (CVSS score: N/A), has been described as a memory corruption issue in dyld, Apple’s Dynamic Link Editor. Successful exploitation of the vulnerability could allow an

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are abusing legitimate remote monitoring tools to hide inside corporate networks and launch ransomware attacks. Net Monitor for Employees Professional is a commercial workforce monitoring tool by NetworkLookout that offers remote screen viewing, full remote control, file management, shell command execution, and stealth deployment. While intended for productivity oversight, these rich administrative capabilities make it […]

    The post Cybercriminals Exploit Employee Monitoring and SimpleHelp Tools in Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple has released emergency security updates for iOS and iPadOS to fix a critical “zero-day” vulnerability that hackers are actively using in attacks. The flaw, tracked as CVE-2026-20700, was discovered by Google’s Threat Analysis Group and is described by Apple as being part of “extremely sophisticated” cyberattacks targeting specific individuals. The Critical Flaw: CVE-2026-20700 The vulnerability […]

    The post Apple 0-Day Flaw Actively Exploited in Targeted Cyberattacks on Individuals appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Recent U.S.-Russian talks about ending Moscow’s war on Ukraine should not be taken as a sign that Russia poses less of a threat to the United States and Europe, according to a new report from Estonia’s foreign-intelligence agency.

    “Despite this illusory thaw, Russia continues to regard the U.S. as its principal global adversary,” says “International Security and Estonia 2026,” released Tuesday.

    Such talks are designed to “exploit the new U.S. administration to restore bilateral relations,” the report says. That could facilitate Russian espionage, influence operations, and the movement of sanctioned goods. Most importantly, it could erode U.S. international influence, creating new opportunities for Russia to expand its own regional dominance.

    The report says Russian leader Vladimir Putin intends such talks to benefit him in two ways: “First, by binding U.S. and Russian interests more closely together; second, by widening what Moscow perceives as existing rifts between the U.S. and Europe.”

    U.S. and other high-ranking officials across NATO member states frequently describe Estonia as a leader in intelligence collection and public dissemination, particularly regarding Russia. Estonia, for instance, accurately predicted Russia’s full-scale invasion of Ukraine in 2022, then moved to provide Ukraine with anti-tank weapons and draw global attention to Moscow's plans.

    The restoration of U.S.-Russian relations may not be viewed as damaging by the current White House. The National Security Strategy released in December does not explicitly call Russia a threat, as previous strategies have. Instead, the NSS calls for “strategic stability” with the Kremlin, while echoing Russian criticisms of the European Union for its "current trajectory." 

    The Estonian report notes that Moscow’s official messaging frames European states as more hostile than the United States, which remains treaty allies with many of them.

    Some White House observers and high-ranking defense officials have suggested that normalizing relations with Russia could pull Moscow away from Beijing to isolate China—a strategy often called the “reverse Kissinger.” 

    But China-Russia cooperation is deepening, as noted by the Estonian report and the Munich Security Report 2026, released Monday.  

    “China and Russia present a united front internationally in their pursuit of an alternative governance model intended to marginalize Western states,” says the Munich report. 

    The report adds that Moscow's propaganda frames the war in Ukraine as a “civilizational struggle between Russia and the West,” led by Washington. 

    China is filling the voids left by the U.S. retreat from international institutions and the implementation of aggressive tariffs. 

    As the Munich report observes, “For countries such as Brazil, U.S. trade pressure has hardened their stance vis-à-vis Washington and could push them closer to Beijing. Indeed, China has happily stepped into the void left by the U.S. retreat from global trade.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Marines have tapped one of the companies competing to build the Air Force’s drone wingman to help develop its own Corps-specific Collaborative Combat Aircraft program, a key element of its new aviation plan.

    Nearly two years after the Air Force chose General Atomics Aeronautical Systems Inc. to compete for its robot wingman concept, the Marine Corps is paying the company to supply a YFQ-42A to use as a testbed for CCA concepts and gear, the company said in a Tuesday announcement.

    The work will be evaluated as part of the Marine Corps Air-Ground Task Force Uncrewed Expeditionary Tactical Aircraft, or MUX TACAIR, CCA program—one of the top priorities of the 2026 Marine Aviation Plan, which was also released on Tuesday.

    The Marines’ CCA effort is meant to ”increase the survivability and lethality” of the service’s F-35B jets “across a wide range of developing threat environments,” the plan said.

    GA isn’t the only company involved in the Marines’ CCA program. Last month, the Corps selected Northrop Grumman and Kratos to develop the CCA itself. Northrop was tapped to develop a mission kit and open-architecture software for Kratos’s existing VX-58 Valkyrie. 

    The Marines’ 2026 request for $58 million in CCA-related funding was signed into law in the latest National Defense Authorization Act, adding to the $275 million in reconciliation funding approved in July. 

    General Atomics didn’t say how much they would receive for their work, but did say it involves “rapid development of autonomy” for a kit focused on kinetic and non-kinetic effects “for use in expeditionary operations.”

    “The YFQ-42A successfully conducted its maiden flight in August 2025, validating a ‘genus/species’ concept for rapid, modular, and low-cost uncrewed fighter aircraft development,” the announcement said. “This approach enables a common core aircraft design that can be rapidly adapted for different mission sets and service requirements.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Drone boat makers say they’re ready for the U.S. Navy to start testing their wares.

    “I don't think anyone questions whether unmanned has a place in the fleet architecture,” Blue Water Autonomy CEO Rylan Hamilton told Defense One. “It's really: ‘How long is it going to take to get some of these vessels out into the fleet and operating, so the end user of the fleet can really figure out how they want to use them and how many they actually want?’” 

    Speaking ahead of this week’s WEST conference in San Diego, Hamilton said his two-year-old company has been intensively testing its first product, an 800-ton, nearly-200-foot autonomous surface vessel. He said the craft, dubbed Liberty Class, has endured more than a thousand hours at sea since the new year.

    “We've been able to raise private capital from firms like Google Ventures, and we've used that to basically test everything on the ocean seven days a week,” he said. “We know we're not going to be perfect out of the gate. And so it's been really important for us to take everything we develop and just test it and take it through as many cycles as possible before we actually put it on a production ship.” 

    Blue Water aims to put the Liberty into production later this year at Conrad Shipyard in Louisiana. Hamilton wouldn’t say how many would be built, but said the shipyard can produce more than 20 similarly sized vessels a year.

    “Right now, the focus really should be on the suppliers and not the Navy. I think the Navy's given all the right signals. They've given all the right contract mechanisms to allow industry to move fast. And now what I think the Navy and the end user needs is to see the performance of these vessels,” Hamilton said. “They need to see that they actually meet the requirements and they actually serve the end user and the fleet in terms of being reliable.”  

    Welcome

    You’ve reached the Defense Business Brief, where we dig into what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and rooftop recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends and foes to subscribe!

    CNO looks at robots, AI, and additive manufacturing in fighting instructions released ahead of his keynote opening speech Tuesday at the WEST conference in San Diego. 

    Robotic and autonomous systems “are an important feature of the current and future force. Yet by treating these systems as novel, we carve them out of the standard model and reduce options and fungibility in fielding them at scale,” Caudle writes in the document. “The Navy must clarify how Fleet Commanders and the Joint Force can express demands for RAS capabilities and effects” and “address the associated doctrinal shortfalls, organizational seams, and process gaps, including determining how we will allocate RAS in service decisions like strategic laydown, dispersal, and global force management.”

    But the chief of naval operations isn’t quite ready to pen a standalone unmanned or robotic systems strategy, he told attendees Tuesday during Q&A following his WEST speech.

    “I'm not ready to do that yet. We're in this discovery phase of how we…assemble command and control of these forces through the administrative chain command, so we can actually field to maintain, sustain and train sailors to actually bring these kinds of capabilities to bear,” he said.

    However, Caudle said he could easily see robotics and autonomous systems, or RAS, commanders as part of a carrier strike group’s staff, alongside those for air missile defense and information warfare, “to advise that strike group commander.”

    The Navy has already experimented and employed autonomous systems with Task Force 59, Fourth Fleet, and Naval Forces Europe, he said. But “I need to understand this a little bit more…before I go pen the paper on how it's going to look in the future.”

    Caudle also spotlighted advanced manufacturing during his keynote.

    “I just had this opportunity at [Naval Station Rota] to see this incredible demonstration of advanced manufacturing there on specific components—large-scale, metal components—that the Arleigh Burkes there in Rota need,” he said. “I did not know to the extent that that capability exists at that level. So those are the types of things I want to scale” to help speed up maintenance.

    Arms exports. The Pentagon has made good on one of its acquisition reform goals: moving the Defense Security Cooperation Agency and Defense Technology Security Administration from its policy shop to its acquisition shop, defense officials announced on social media Tuesday. 

    “This realignment has created a single, coherent defense-sales enterprise within the department,” Michael Duffey, the Pentagon’s chief weapons buyer, said in a video posted on X. “We’ll proactively target sales that unlock foreign investment to help power critical production lines, fueling companies to invest in new manufacturing plants, hire more engineers and create thousands of well-paying American jobs, all while better equipping our partners to share the burden of their own conventional defense.”

    On Feb. 6, President Trump ordered the Pentagon to prioritize foreign arms sales to countries that have increased their defense spending and focus on certain domestic-made weapons. 

    ICYMI: The Pentagon is definitely reviewing defense contractors’ performance, as promised in an earlier executive order, but is stopping short of naming which ones are under review. 

    What I’m curious about: Will these reviews result in any actual change for contractors, how long will they last, and will they steer future contract awards. TBD for now.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered what they said is the first known malicious Microsoft Outlook add-in detected in the wild. In this unusual supply chain attack detailed by Koi Security, an unknown attacker claimed the domain associated with a now-abandoned legitimate add-in to serve a fake Microsoft login page, stealing over 4,000 credentials in the process. The activity has been

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶